CVE-2025-43788: Medium severity Liferay portal vulnerability
The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43788?
CVE-2025-43788 has been classified as a critical vulnerability due to its potential impact on information disclosure.
How do I fix CVE-2025-43788?
To remediate CVE-2025-43788, ensure you update to the latest versions of Liferay Portal and Liferay DXP that are free from this vulnerability.
What types of systems are affected by CVE-2025-43788?
CVE-2025-43788 affects Liferay Portal versions 7.4.0 through 7.4.3.124 and Liferay DXP versions 2024.Q1.1 through 2024.Q1.12.
What is the risk of CVE-2025-43788?
The risk associated with CVE-2025-43788 includes remote authenticated users being able to view all organizations without permission.
Can CVE-2025-43788 be exploited remotely?
Yes, CVE-2025-43788 can be exploited remotely by authenticated users who can access the affected Liferay systems.